Score
Designs and executes measurement campaigns and test benches to collect and preprocess side‑channel signals (power and electromagnetic traces), and implements feature extraction and compact feature‑selection pipelines to isolate outcome‑revealing signal components. Builds and evaluates leakage quantification and detection procedures and trains attack models to rank features, measure secret recoverability, and assess the strength of leakage‑driven shortcuts or countermeasures.
This study addresses the instability of side-channel leakage detection caused by variations in electromagnetic probe placement, which severely limits the transferability of cross-device attacks. To overcome this challenge, the authors propose a unified deep learning model trained on electromagnetic traces collected simultaneously from multiple probe positions, enabling, for the first time, effective capture of leakage information across a larger area of the target chip. This approach significantly enhances the robustness and transferability of side-channel attacks under varying probe locations and across different devices. The method’s stability and effectiveness in cross-environment attack scenarios are rigorously validated using datasets acquired independently in two distinct laboratories.
This work demonstrates that public release of spectral density statistics can inadvertently leak hidden configuration parameters of generative models. To address this, the authors propose a statistical side-channel auditing framework based on a gamma- and covariance-weighted log-spectral channel model, employing Kullback–Leibler divergence and Chernoff information to quantify information leakage. The study establishes a ninth-order relationship among leakage magnitude, bandwidth, and sample size under finite-bandwidth constraints, derives closed-form expressions for secure bandwidth thresholds, and provides tight upper bounds on both information leakage and adversarial advantage. The theoretical findings are validated through an extreme ultraviolet roughness spectrum case study. The paper also includes a fully reproducible protocol and open-source implementation to facilitate independent verification and extension.
This work addresses the lack of efficient and scalable tamper detection mechanisms for microcontrollers in semiconductor supply chains, where existing high-assurance approaches are often costly and slow. The authors propose a non-invasive screening method that, for the first time, leverages a generative adversarial network (GAN) trained exclusively on benign samples to analyze out-of-band power side-channel signals. This enables one-class anomaly detection without requiring trusted hardware or labeled data. By integrating differential power analysis with generative modeling, the approach demonstrates effectiveness across diverse firmware and hardware Trojan scenarios. It establishes an intermediate assurance tier between rapid screening and expensive forensic analysis, offering a practical tool that balances efficiency and reliability for supply chain security.
This work proposes SCAgent, a novel framework that leverages large language model (LLM) agents for automated side-channel discovery and verification—a task traditionally reliant on manual effort and challenging to scale in complex systems. SCAgent generates hypotheses through semantic reasoning over system documentation, mitigates hallucination via explicit verification mechanisms and semantic consistency constraints, and introduces time-shift-robust temporal features tailored for foundation models to enable efficient few-shot analysis. Evaluated on iOS, the framework successfully reproduces classic fingerprinting attacks and uncovers multiple previously unknown sensitive activities, demonstrating its capability to automatically and accurately identify side-channel vulnerabilities even with limited data.
This study addresses the issue that real-time monitoring in side-channel evaluation often leads to uncontrolled false positive rates under fixed-threshold testing. To overcome this, it proposes a betting-based testing framework utilizing SKIT-type swap e-processes for electromagnetic traces of ML-KEM. Under an explicitly conditionally symmetric null hypothesis, the method achieves anytime-valid leakage detection with strict, uniform control of the false positive probability across the entire time domain. Although the approach requires 1.7–2.4 times more data than conventional methods, it supports early stopping—consuming only 2–8% of the measurement budget—and significantly mitigates the risk of false positives induced by repeated peeking. Consequently, this work provides a reliable statistical framework for dynamic side-channel monitoring.
This work addresses the challenges of limited scalability and insufficient attribution accuracy in identifying root causes of power side-channel leakage during pre-silicon processor design. The paper introduces SPARC, a novel framework that enables, for the first time, automated and highly accurate end-to-end leakage detection and root-cause tracing in the pre-silicon phase. SPARC achieves this by performing macrocell-level information flow tracking and employing enhanced shadow logic to tag key-dependent switching activity, which is then correlated with software instructions through statistical leakage testing. Evaluation on multiple open-source RISC-V processors demonstrates that SPARC not only reproduces known vulnerabilities but also uncovers previously unknown microarchitectural side channels, while achieving an 8× speedup in single-trace simulation compared to existing approaches.
本文提出LeakGauge方法,通过在响应中添加后缀来检测大语言模型处理外部上下文时的泄露风险,该方法在11个模型上表现出高稳定性与准确性。
This work addresses critical limitations in existing cybersecurity reconnaissance tools—namely low accuracy, poor stealth, inefficiency, and insufficient scalability—by proposing and implementing a fingerprint-driven, automated reconnaissance and vulnerability validation framework. The framework tightly integrates target fingerprinting with proof-of-concept (PoC) verification, enabling end-to-end automation of reconnaissance, in-depth data processing, and vulnerability detection. By coupling the reconnaissance and validation phases into a unified workflow, the approach significantly enhances system automation, usability, and extensibility. Experimental evaluation in simulated environments demonstrates that the tool efficiently executes comprehensive reconnaissance-to-validation pipelines, substantially improving the effectiveness and speed of offensive and defensive cyber operations.
This work addresses the vulnerability of deep learning hardware deployed in safety-critical domains such as healthcare and finance to side-channel attacks, which can lead to the leakage of model architectures, parameters, and sensitive user data. The study systematically surveys existing vulnerabilities and presents the first comprehensive taxonomy of side-channel attack surfaces and defense strategies tailored to deep learning accelerators. By integrating hardware microarchitectural characteristics with physical leakage modeling, it establishes a holistic threat analysis framework that encompasses attack objectives, leakage sources, and mitigation mechanisms. Beyond clarifying the research landscape of current techniques, this paper identifies key challenges and outlines promising directions for future work, thereby offering both theoretical foundations and practical guidance for designing secure deep learning systems.
This work addresses the inefficiency of traditional fuzzing in black-box or obfuscated binary programs where static instrumentation is infeasible and control-flow feedback is unavailable. The authors propose a dynamic feedback mechanism based on Execution Divergence Graphs (EDGs), which constructs control-flow-like structures at runtime by analyzing execution traces to precisely identify path divergences and avoid redundant exploration of loops. Requiring no static program information, the approach integrates divergence detection with an EDG-guided input mutation strategy. Evaluated on multiple obfuscated targets, it substantially outperforms blind fuzzers, demonstrating its effectiveness in non-instrumented settings. Furthermore, the framework is extensible to multidimensional feedback channels, such as power consumption, broadening its applicability in side-channel-aware fuzzing scenarios.